How do I send secure email if I can’t use NHSmail?
Who can get NHSmail, how the NHS secure email standard (DCB1596) works, and the secure options for private GPs emailing patients and NHS GP practices.
The short answer
Most purely private practices cannot get NHSmail (now NHS.net Connect), so NHS secure email for a private GP means one of three things: encrypting clinical email at message level, accrediting your own email service to the NHS secure email standard (DCB1596), or avoiding email altogether by sending letters to NHS GPs over MESH. For anything clinical sent from an ordinary business account, use message-level encryption, and put letters to NHS GPs through MESH where you can.
Key points
- NHSmail (NHS.net Connect) is for organisations providing or supporting publicly funded care, so most purely private practices cannot get it.
- Under the NHS secure email standard (DCB1596), mail between NHSmail and other secure or accredited domains is secure. Ordinary business email is not, so encrypt clinical content.
- Organisations can accredit their own Microsoft 365, Google Workspace or self-managed email to DCB1596. NHS England publishes the list of accredited domains, and it includes private providers.
- Send letters to NHS GPs over MESH where possible, rather than by email.
- Use a practice mailbox, keep clinical messages in the record, and treat every email tool as a data processor.
For a private GP, NHS secure email rarely means having an nhs.net address. NHSmail is for organisations providing or supporting publicly funded care, so most purely private practices cannot join it. Instead, encrypt clinical emails at message level, send letters to NHS GPs over MESH rather than email, and, if you email the NHS a lot, consider accrediting your own email service to the NHS secure email standard (DCB1596).
NHS secure email: who can and cannot get NHSmail
NHSmail has been renamed NHS.net Connect, and addresses still end in @nhs.net. NHS England says anyone who works for the NHS can use it if their organisation has been approved. For independent organisations, the route is for those providing NHS services nationally: the application asks for an ODS code, a business justification based on your relationship with NHS organisations and an up-to-date Data Security and Protection Toolkit (DSPT), and independent providers are limited to 50 accounts. If you are commissioned locally by an ICB or NHS trust that requires NHSmail, the commissioner should provide sponsored accounts for the length of the contract.
So if you hold an NHS contract, ask your commissioner. If your practice is purely private, plan on not having NHSmail. An older version of this page said all private GPs should now be able to get it, which is not right. See can I use NHSmail as a private GP?
The NHS secure email standard (DCB1596)
NHS England says emails sent to and from health and social care organisations must meet the secure email standard, DCB1596, so that sensitive and confidential information stays secure. NHSmail guidance treats these addresses as secure with no extra steps: *.nhs.net, *.nhs.uk addresses on accredited systems, and some government domains such as *.gov.uk, *.cjsm.net and *.police.uk.
Organisations that are not on NHSmail can accredit their own email service. NHS England publishes the list of accredited domains, last updated on 1 October 2026 at the time of review. It lists around 300 domains, mostly running Microsoft 365 or Google Workspace, and includes private providers such as Bupa, Nuffield Health and Circle Health Group as well as NHS trusts. The list also records each domain’s DMARC, SPF, DKIM and TLS settings, which gives a sense of the technical bar.
NHS England Digital says Microsoft 365 accreditation typically takes one to three months and a self-managed service six months to a year, and you must re-accredit every year. It is a realistic option for a group that emails NHS organisations every day. For a small practice, the other options below are usually simpler.
What [secure] means
When an NHSmail user needs to send sensitive information to an address that is not secure, such as a patient’s or a private practice’s ordinary email, they add [secure], with the square brackets, to the subject line. NHSmail encrypts the message, and the recipient registers once and reads it in a web browser. If an NHS colleague needs to send you clinical information and your domain is not accredited, you can ask them to use [secure].
What “secure” actually means
Most email services encrypt messages while they travel between servers. That helps, but it does not protect you from the commonest email breach: sending the wrong thing to the wrong person. The ICO describes a case where a file of special category data about 241 people was emailed to the wrong address with no encryption or password, so everyone who received it could open it.
For clinical information, use message-level encryption. The recipient has to prove who they are, for example with a one-time code or a password, before they can read the message. If it goes to the wrong address, the wrong person cannot open it.
Secure email options for private GPs
| Option | How recipients read it | Points to check |
|---|---|---|
| Encryption built into your business email | In their own email app, or on a web page after a one-time code | Which plan includes it; how easy it is for patients |
| A dedicated encrypted email service | Through a secure link, often with a password | How the password is shared; message expiry; reply limits |
| Secure messaging in your record system or portal | Patient logs in to read and reply | Patients need an account; messages stay with the record |
| Accreditation to DCB1596 | Normally, with protection to and from NHSmail | Annual re-accreditation; effort involved |
| MESH, for letters to NHS GPs | Arrives in the GP practice’s document workflow | Your own mailbox, a transfer service or a record system that sends over MESH |
Encryption in business email
Microsoft 365 includes Microsoft Purview Message Encryption in Business Premium and the Enterprise E3 and E5 plans. It can be added to Business Basic and Business Standard with an Azure Information Protection Plan 1 licence. Recipients outside Microsoft 365, including Gmail users, can read and reply in a web browser. Google Workspace’s client-side encryption was only available on the Enterprise Plus, Frontline Plus and Education Standard and Plus editions at the time of review, not on the Business plans most small practices use. On a Business plan, add a dedicated encrypted email service. Either way, confirm exactly what your plan includes before relying on it.
Dedicated encrypted email
Some email services are built around encryption. Proton Mail, for example, lets you send password-protected emails to people who do not use Proton, on all its plans. They expire after 28 days at most, the recipient can reply up to five times, and you share the password separately. Always send a password by a different route, such as a text or phone call, never in the same email. This is message-level encryption, not DCB1596 accreditation, so it does not make your domain “secure” in NHSmail’s terms.
A secure portal or messaging tool
Many record systems include secure patient messaging. It keeps the conversation with the patient’s record and avoids email addresses going astray. It works best for patients you see regularly, because they need to log in.
How to email an NHS GP practice securely
For letters to a patient’s NHS GP, email is not the best route. MESH, the NHS’s secure messaging service, puts the letter straight into the practice’s document workflow, the same way hospital letters arrive. NHS England says any health and social care organisation with a valid use case can use it and that it is free, though setting up your own mailbox takes from a week or two to a month or more. You can also send through a document transfer service or a record system that sends over MESH. A good example of the last is Jump EHR, a private GP record system that sends letters to the patient’s NHS GP via MESH from the record. Other routes are compared in sending notes to the NHS GP.
When you do need to email an NHS GP practice:
- Get the right address. Use the practice’s shared nhs.net address, not a named individual, unless you know who should receive it.
- Encrypt from your side. Unless your own domain is DCB1596-accredited, send with message-level encryption. An nhs.net recipient does not make the message secure on its own.
- Send the minimum. Include what the GP needs to act, with identifiers, and keep names and conditions out of the subject line.
- Ask for replies via [secure]. If the practice needs to send clinical information back to you, ask them to use [secure] in the subject line.
- Record it. Keep a copy or summary in the patient’s record, with the patient’s consent to share noted.
Emailing patients
NHS England’s guidance on messaging patients is a sensible model. You do not need consent to email patients about their own care, but keep confidential detail out of unencrypted messages, respect their preferences, and keep a copy or summary in the record. If a patient asks you to use ordinary email, explain the risk, record their wishes and still send the minimum detail needed.
Managing the practice inbox
An older article on this site asked which email system is best. There is no single answer, but a few principles hold.
- Use a practice address, not a personal one. A shared mailbox or group address lets colleagues cover leave and keeps the practice in control.
- Consider a helpdesk tool as you grow. Products such as Freshdesk, Zendesk and Front turn emails into tickets that can be assigned, tracked against response times and answered with saved replies. They suit busier practices with admin staff.
- Keep the clinical record in the record. Whatever tool you use, copy clinically relevant messages into the patient’s record. The inbox is not the record.
- Treat every tool as a processor. Anything that stores patient emails needs a data processing contract, and you should know where the data is hosted. See GDPR compliance in private practice.
Habits that prevent breaches
- Check the recipient before you press send, especially with autocomplete.
- Use a short send delay so you can recall a mistake.
- Keep patient names and conditions out of subject lines.
- Turn on multi-factor authentication for every mailbox.
- Train staff to spot phishing, and report suspicious messages.
Outside England
DCB1596, NHS.net Connect and the accredited domains list are English arrangements. NHS organisations in Scotland, Wales and Northern Ireland use their own email services, so ask how they prefer to receive information from independent providers. UK GDPR and ICO guidance apply across the UK.
Frequently asked questions
Can a private GP get an NHS secure email address?
Usually not. NHSmail (NHS.net Connect) is for organisations providing or supporting publicly funded care. If you hold an NHS contract, ask your commissioner about sponsored accounts. Otherwise use encrypted email, or accredit your own email service to DCB1596.
Is sending to an nhs.net address secure on its own?
Only if your own email service is also secure under the standard, for example DCB1596-accredited. From an ordinary business account, encrypt the message at your end.
Is Gmail or Outlook secure enough on its own?
Standard personal accounts are not suitable for patient data. Use a business account with multi-factor authentication and add message encryption for clinical content.
Can I just password-protect a PDF attachment?
It is better than nothing if you use a strong password and share it by a separate route, as the ICO advises. A proper encryption service is easier to use consistently.
What if a patient cannot open encrypted email?
Offer another secure route, such as a portal message, a phone call or post. If they choose ordinary email, explain the risk, record their preference and send the minimum detail.
Do I need to keep copies of emails?
Keep clinically relevant emails, or a summary, in the patient’s record. Set a retention period for the inbox itself so old messages do not pile up.
Sources
- NHS.net Connect (formerly NHSmail)
- NHSmail application process for nationally commissioned/independent organisations providing or supporting publicly funded health and social care in England (v6.0, June 2023)
- The secure email standard
- DCB1596 accredited domains (CSV)
- The accreditation process (DCB1596)
- Guidance for sending secure email (including to patients)
- Message Exchange for Social Care and Health (MESH)
- Encryption scenarios
- Message Encryption FAQ
- About client-side encryption
- Password-protected emails
- Texting, emailing and messaging patients and service users: guidance for health and care professionals